- CheckMates
- :
- Products
- :
- CloudMates Products
- :
- CloudMates General
- :
- Re: Update IPS signatures without default
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Update IPS signatures without default
Hello, everyone.
I have moved HA cluster from static to OSPF. HA cluster is installed in the center of the network and receives the default from the upstream router.It turns out that the active node has a default by OSPF, but the passive node does not receive the default. When we switch nodes, the situation is the same. I.e. in SMS, the passive node always gets an error that it cannot connect to CheckPoint to update the databases.
Alternatively, it is possible to write all subnets of update portals by statics. But this is not a good option I think, because the subnets can change.
Maybe you can suggest something more correct?
If I decide to write static routes to the CheckPoint update portal, do you know which subnets are needed? If there is a list, please tell me where to see it.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm pretty sure the passive member should also have the default route as well.
Both members should have the same router-id (cluster address).
See: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello.
I was check OSPF configuration on both nodes and see no problem in it. The default was added statically, but on standby node I do not see it in routing table.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
"HA cluster is installed in the center of the network and receives the default from the upstream route" - it was incorrect information. The default on the gateway was set statically. The other routes came via OSPF. The IP address of the default route gateway should have been pinged by configuration. For the backup node, this setting means removing the default route from the routing table even if the gateway is pinged.